Live data from Hacker News

About the security content of iOS 7.0.6

support.apple.com

11–20 of 155 posts

Re: About the security content of iOS 7.0.6

#11
post #10
post #9

[deleted]

https://gist.github.com/rmoriz/fb2b0a6a0ce10550ab73 http://i.imgur.com/CoALymQ.png (i've not checked that on iOS or Apple TV just on OSX. Maybe it's another issue but the update description pretty much fits too well ;-)

Holy shit! So they are really not checking the CN and knew it since 2013-11-28. I've lost the last bit of respect I had for apple (that was mostly building webkit) now.

(I deleted my gp, because it's pretty much obsolete now with your full disclousure. Thanks!)

Re: About the security content of iOS 7.0.6

#12
post #10
post #9

[deleted]

https://gist.github.com/rmoriz/fb2b0a6a0ce10550ab73 http://i.imgur.com/CoALymQ.png (i've not checked that on iOS or Apple TV just on OSX. Maybe it's another issue but the update description pretty much fits too well ;-)

So OS X as well as iOS?

Re: About the security content of iOS 7.0.6

#13
post #10

Earlier quoted context omitted.

https://gist.github.com/rmoriz/fb2b0a6a0ce10550ab73 http://i.imgur.com/CoALymQ.png (i've not checked that on iOS or Apple TV just on OSX. Maybe it's another issue but the update description pretty much fits too well ;-)

So OS X as well as iOS?

I think so but I only discovered the OSX issue.

Re: About the security content of iOS 7.0.6

#15
post #5

Sounds like a classic Man-in-the-Middle (MITM) attack. Just a guess, but from the short description I suspect if you have control over DHCP you can get iOS to use your proxy. From there you can use something like mitmproxy ( http://mitmproxy.org/ ) to forge SSL certificates on the fly and intercept and decrypt SSL traffic without any warnings showing up on the iOS device.

You can do that but you'll be throwing certificate errors everywhere if they're self signed. By the sounds of it this is a bypass or method of getting around the CA altogether.

Yes, normally certificate errors would be thrown.

In this case Apple is not performing the domain validity checks on the presented cert. This allows an attacker that is performing an mitm attack to present a valid cert for another domain and establish an SSL connection with the victim.

Re: About the security content of iOS 7.0.6

#17
post #4

Does this contain patches for the jailbreak?

No, apparently. See https://twitter.com/winocm/status/436923366147375104 and https://twitter.com/winocm/status/436923608762695680 for a jailbreak developer saying that it doesn't seem to fix any jailbreak bugs. He's not one of the developers of the iOS 7 jailbreak, but he knows what he's talking about.

Re: About the security content of iOS 7.0.6

#19

Heh... "congrats to the Apple iOS team on adding SSL/TLS hostname checking in their latest update! very cool feature." https://twitter.com/will_sargent/status/436985812878491648

Comedic derision appreciated :)

However this is a pretty damn serious oversight.

I've just shut down my MacBook and picked up my ThinkPad.

Re: About the security content of iOS 7.0.6

#20
If I believe [1], 4% of all the iOS devices are still on versions earlier than 6, and will not be patched to this specific issue. This is pretty severe. I wonder (but presume not) if Apple is going to issue patches for earlier versions.

[1] http://appleinsider.com/articles/13/12/31/ios-7-now-installe...

Post reply on HN